CVE-2026-26083

Published May 12, 2026

Last updated 24 days ago

Overview

Description
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortisandbox, fortisandbox_cloud, fortisandbox_paas

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@fortinet.com
CWE-862

Social media

Hype score
Not currently trending
  1. Warning: 1 critical, 1 high, 3 medium vulnerabilities in #Fortinet #FortiOS #FortiSandbox #FortiAP #FortiAnalyzer #FortiManager #CVE-2026-26083 #CVE-2025-53844 #CVE-2025-53870 #CVE-2025-53680 #CVE-2025-67604 CVSS: 9.8-5.3 See: https://t.co/eiPZ3NXU8S & https://t.co/qFyxni6az

    @CCBalert

    14 May 2026

    377 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) | Codebook https://t.co/NmqQTMQ0Hh "Fortinetはこれらの脆弱性が実際の攻撃で悪用されているとは述べていないが、同社製品の

    @catnap707

    13 May 2026

    373 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  3. 🚨 Alertes sécurité : CVE-2026-26083 et CVE-2026-44277 sur FortiSandbox et FortiAuthenticator Des failles FortiSandbox et FortiAuthenticator permettent l'exécution de commandes à distance sans authentification. Plus d'informations : https://t.co/b1RGecowT0

    @LoginSecurite

    13 May 2026

    72 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) | Codebook|Security News https://t.co/35erJvPlqj

    @ohhara_shiojiri

    13 May 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨Fortinet、FortiSandboxとFortiAuthenticatorの重大なRCE脆弱性について警告(CVE-2026-44277、CVE-2026-26083) 🩹マイクロソフト、5月の月例パッチで脆弱性120件を修正 ゼロデイは含まれず(CVE-2026-35421、CVE-2026-40365他) 〜

    @MachinaRecord

    13 May 2026

    189 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. @Fortinet warns of 2 critical RCE flaws CVE-2026-44277 (FortiAuthenticator): Unauthenticated RCE via improper access control. Fixed in 6.5.7 / 6.6.9 / 8.0.3 (Cloud not affected). CVE-2026-26083 (FortiSandbox): Missing authorization leading to RCE on WEB UI. Patch ASAP — Fortin

    @ByteCheck101

    13 May 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 Fortinet emergency patch: Two critical RCE flaws (CVSS 9.1 each) in FortiSandbox and FortiAuthenticator. CVE-2026-44277 — unauthenticated RCE in IAM solution CVE-2026-26083 — unauthenticated RCE via WEB UI 🔗 https://t.co/xtQEQeE0Nn #CyberSecurity #ThreatIntel #Fort

    @ThreatAft

    13 May 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. NEW: Fortinet CRITICAL unauth RCE - CVE-2026-44277 FortiAuthenticator & CVE-2026-26083 FortiSandbox. 9 detections, 24 IOCs. https://t.co/lq48SknZJx #ThreatIntel #Fortinet #CVE https://t.co/tuiH0Y15oG

    @threadlinqs

    13 May 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Fortinet Critical RCE Flaws Fortinet patches two critical RCE vulnerabilities in FortiSandbox (CVE-2026-44277, CVE-2026-26083) and FortiAuthenticator (CVE-2026-21643, CVE-2026-35616). Unauthenticated attackers can run arbitrary commands or code on affected appliances. No

    @ElusivePrivacy

    12 May 2026

    123 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.